- Sources: paper, HN discussion
- Summary: The USENIX Security paper analyzes group messaging in the major end-to-end encrypted messengers and reports that none of them provide transcript consistency. A malicious group member can omit, reorder, or alter content per recipient with no warning surfaced in any user interface. The abstract names Signal, WhatsApp, iMessage and Threema as messengers that have added poll features on top of group messaging, and does not enumerate the full set analyzed. No affected versions are given, because the finding is a design property of the group protocols and their fallback paths rather than a versioned defect in a client build.
- Why it matters: A malicious group member can omit, reorder, or alter content per recipient with no warning in any user interface, so a group transcript and the polls built on top of it cannot be treated as an agreed record.
send feedback on this story